Resource exhaustion in Kibana - CVE-2026-42399
Published: May 29, 2026
Kibana
Detailed vulnerability description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the Timelion visualization expression parser when processing deeply chained function calls in a user-supplied Timelion visualization expression. A remote user can submit a specially crafted Timelion visualization expression to cause a denial of service.
Only deployments where authenticated users have access to the Timelion visualization feature are vulnerable.